jws5-tomcat

Direct Vulnerabilities

Known vulnerabilities in the jws5-tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Authentication Bypass by Primary Weakness

*
  • L
Uncaught Exception

*
  • L
Insecure Default Initialization of Resource

*
  • L
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Cross-site Scripting (XSS)

*
  • L
Insufficient Logging

*
  • L
Detection of Error Condition Without Action

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Authentication Bypass

*
  • L
Open Redirect

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • H
Use of a Risky Cryptographic Primitive

*
  • L
File and Directory Information Exposure

*
  • L
Inappropriate Encoding for Output Context

*
  • M
Incomplete Blacklist

*
  • L
HTTP Request Smuggling

*
  • L
Improper Input Validation

*
  • H
Improper Certificate Validation

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • H
Directory Traversal

<0:9.0.87-14.redhat_00013.1.el8jws
  • H
Resource Exhaustion

<0:9.0.87-14.redhat_00013.1.el8jws
  • M
Authentication Bypass

<0:9.0.87-12.redhat_00011.1.el8jws
  • M
Resource Exhaustion

<0:9.0.87-12.redhat_00011.1.el8jws
  • M
Integer Overflow or Wraparound

<0:9.0.87-12.redhat_00011.1.el8jws
  • M
Race Condition

<0:9.0.87-12.redhat_00011.1.el8jws
  • M
Allocation of Resources Without Limits or Throttling

<0:9.0.87-12.redhat_00011.1.el8jws
  • M
Allocation of Resources Without Limits or Throttling

<0:9.0.87-12.redhat_00011.1.el8jws
  • M
Improper Handling of Case Sensitivity

*
  • H
Improper Neutralization

<0:9.0.87-14.redhat_00013.1.el8jws
  • H
Improper Input Validation

<0:9.0.87-11.redhat_00010.1.el8jws
  • M
Path Equivalence

<0:9.0.87-8.redhat_00008.1.el8jws
  • H
Time-of-check Time-of-use (TOCTOU)

<0:9.0.87-11.redhat_00010.1.el8jws
  • M
Time-of-check Time-of-use (TOCTOU)

<0:9.0.87-6.redhat_00006.1.el8jws
  • H
Resource Exhaustion

<0:9.0.87-5.redhat_00005.1.el8jws
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:9.0.87-5.redhat_00005.1.el8jws
  • H
Missing Required Cryptographic Step

<0:9.0.62-41.redhat_00020.1.el8jws
  • H
Improper Input Validation

<0:9.0.62-41.redhat_00020.1.el8jws
  • H
Incomplete Cleanup

<0:9.0.87-3.redhat_00003.1.el8jws
  • M
Excessive Iteration

<0:9.0.62-19.redhat_00017.1.el8jws
  • M
Resource Exhaustion

<0:9.0.62-19.redhat_00017.1.el8jws
  • M
Resource Exhaustion

<0:9.0.62-19.redhat_00017.1.el8jws
  • M
Improper Certificate Validation

<0:9.0.62-19.redhat_00017.1.el8jws
  • M
Improper Certificate Validation

<0:9.0.62-19.redhat_00017.1.el8jws
  • M
Resource Exhaustion

<0:9.0.62-19.redhat_00017.1.el8jws
  • H
HTTP Request Smuggling

<0:9.0.62-41.redhat_00020.1.el8jws
  • M
Incomplete Cleanup

<0:9.0.62-18.redhat_00016.1.el8jws
  • M
Improper Input Validation

<0:9.0.62-18.redhat_00016.1.el8jws
  • H
Resource Exhaustion

<0:9.0.62-16.redhat_00014.1.el8jws
  • M
Open Redirect

<0:9.0.62-19.redhat_00017.1.el8jws
  • M
Off-by-one Error

<0:9.0.62-15.redhat_00013.1.el8jws
  • M
SQL Injection

<0:9.0.43-11.redhat_00011.1.el8jws
  • M
Information Exposure

<0:9.0.62-15.redhat_00013.1.el8jws
  • M
Allocation of Resources Without Limits or Throttling

<0:9.0.62-15.redhat_00013.1.el8jws
  • M
Integer Overflow or Wraparound

<0:9.0.62-15.redhat_00013.1.el8jws
  • L
Arbitrary Code Injection

<0:9.0.62-13.redhat_00011.1.el8jws
  • L
HTTP Request Smuggling

<0:9.0.62-13.redhat_00011.1.el8jws
  • M
Race Condition

<0:9.0.62-9.redhat_00005.1.el8jws
  • L
Incomplete Documentation of Program Execution

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:9.0.50-5.redhat_00007.1.el8jws
  • M
Time-of-check Time-of-use (TOCTOU)

<0:9.0.62-9.redhat_00005.1.el8jws
  • H
HTTP Request Smuggling

<0:9.0.50-3.redhat_00004.1.el8jws
  • H
Improper Authentication

<0:9.0.50-3.redhat_00004.1.el8jws
  • M
Information Exposure

<0:9.0.36-9.redhat_8.1.el8jws
  • H
HTTP Request Smuggling

<0:9.0.30-3.redhat_4.1.el8jws
  • H
Improper Input Validation

<0:9.0.21-10.redhat_4.1.el8jws
  • H
Missing Release of Resource after Effective Lifetime

<0:9.0.50-3.redhat_00004.1.el8jws
  • H
Resource Exhaustion

<0:9.0.43-13.redhat_00013.1.el8jws
  • H
Out-of-bounds Read

<0:9.0.50-3.redhat_00004.1.el8jws
  • M
NULL Pointer Dereference

<0:9.0.36-9.redhat_8.1.el8jws
  • H
HTTP Request Smuggling

<0:9.0.30-3.redhat_4.1.el8jws
  • H
Race Condition

*
  • L
Improper Input Validation

*
  • M
Improper Access Control

*
  • H
Integer Overflow or Wraparound

<0:9.0.50-3.redhat_00004.1.el8jws
  • M
Deserialization of Untrusted Data

<0:9.0.43-11.redhat_00011.1.el8jws
  • M
Information Exposure

<0:9.0.43-11.redhat_00011.1.el8jws
  • H
NULL Pointer Dereference

<0:9.0.50-3.redhat_00004.1.el8jws
  • H
Deserialization of Untrusted Data

<0:9.0.30-4.redhat_5.1.el8jws
  • H
Improper Authorization

<0:9.0.30-3.redhat_4.1.el8jws
  • M
Information Exposure

<0:9.0.36-9.redhat_8.1.el8jws
  • H
Resource Exhaustion

<0:9.0.30-5.redhat_6.1.el8jws
  • M
Information Exposure

<0:9.0.36-9.redhat_8.1.el8jws
  • H
Resource Exhaustion

<0:9.0.30-5.redhat_6.1.el8jws
  • M
Resource Exhaustion

<0:9.0.36-6.redhat_5.2.el8jws
  • H
Session Fixation

<0:9.0.30-3.redhat_4.1.el8jws
  • H
Missing Required Cryptographic Step

<0:9.0.21-10.redhat_4.1.el8jws
  • H
Improper Access Control

<0:9.0.30-3.redhat_4.1.el8jws
  • H
Resource Exhaustion

<0:9.0.21-10.redhat_4.1.el8jws
  • H
Cross-site Scripting (XSS)

<0:9.0.21-10.redhat_4.1.el8jws
  • H
Resource Exhaustion

<0:9.0.21-10.redhat_4.1.el8jws
  • H
Information Exposure

<0:9.0.21-10.redhat_4.1.el8jws